Alerts This Week
Warning Icon 1 1,082
Alerts This Week
Warning Icon 1 1,082

Debian 11 calibre DLA-4554-1 Path Traversal and File Write Risks

debian lts
Calendar Grey April 30, 2026
Dist Debian Esm H88
Multiple vulnerabilities in calibre e-book manager could allow file writes and code execution in Debian systems.
Multiple vulnerabilities have been discovered in calibre, an e-book manager CVE-2025-64486 calibre does not validate filenames when handling binary assets in FB2 files, allowing an...

Summary

CVE-2025-64486

calibre does not validate filenames when handling binary assets in
FB2 files, allowing an attacker to write arbitrary files on the
filesystem when viewing or converting a malicious FictionBook
file. This can be leveraged to achieve arbitrary code execution.

CVE-2026-25635

Calibre's CHM reader contains a path traversal vulnerability that
allows arbitrary file writes anywhere the user has write
permissions.

CVE-2026-25636

a path traversal vulnerability in Calibre's EPUB conversion allows
a malicious EPUB file to corrupt arbitrary existing files writable
by the Calibre process

CVE-2026-26064

a path traversal vulnerability that allows arbitrary file writes
anywhere the user has write permissions.

CVE-2026-26065

Path Traversal through PDB readers that allow arbitrary file
writes with arbitrary extension and arbitrary content anywhere the
user has write permissions. Files are written in 'wb' mode,

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: calibre
Version: 5.12.0+dfsg-1+deb11u4
CVE ID: CVE-2025-64486 CVE-2026-25635 CVE-2026-25636 CVE-2026-26064

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here